What is the most likely reason the traffic is being denied?
Exhibit
Refer to the exhibit. Application Command Center Name: myapp Category: business-systems Subcategory: file-sharing Technology: peer-to-peer Risk: 4 Characteristics: evasive-behavior, used-by-malware, excessive-bandwidth Security Policy Rule: Source: any Destination: any Application: myapp Action: allow Profile: default Logs show traffic matching this rule is being denied with action 'reset-both'.
Trap 1: The application is not actually matching the rule.
Logs show the rule is matched.
Trap 2: A DoS protection policy is blocking the traffic.
DoS protection would not typically reset.
Trap 3: App-ID is incorrectly identifying the traffic.
The exhibit shows myapp is identified.
- A
The application is not actually matching the rule.
Why wrong: Logs show the rule is matched.
- B
A threat prevention profile is blocking the application due to its 'evasive-behavior' characteristic.
Evasive applications are often blocked by default profiles.
- C
A DoS protection policy is blocking the traffic.
Why wrong: DoS protection would not typically reset.
- D
App-ID is incorrectly identifying the traffic.
Why wrong: The exhibit shows myapp is identified.